Fake_AdobeReader_EXE
Description
Detects an fake AdobeReader executable based on filesize OR missing strings in file
Query · yara
strings:
$s1 = "Adobe Systems" ascii
$fp1 = "Adobe Reader" ascii wide
$fp2 = "Xenocode Virtual Appliance Runtime" ascii wide
condition:
uint16(0) == 0x5a4d and
filename matches /AcroRd32.exe/i and
not $s1 in (filesize - 2500..filesize)
and not 1 of ($fp*)